Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <0c6e9ffe-f3da-47dd-9d53-d0dcdb4c435d@gmail.com>
Date: Wed, 29 Apr 2026 17:12:49 -0700
From: Goutham Pacha Ravi <gouthampravi@...il.com>
To: oss-security@...ts.openwall.com
Subject: OSSA-2026-008: OpenStack Ironic: Command Injection in Ironic IPMI
 Console Implementations (CVE-2026-42510) - errata 1

=======================================================================
OSSA-2026-008: Command Injection in Ironic IPMI Console Implementations
=======================================================================

:Date: April 27, 2026
:CVE: CVE-2026-42510


Affects
~~~~~~~
- Ironic: >=4.3.0 <26.1.6, >=27.0.0 <29.0.5, >=30.0.0 <32.0.1, >=33.0.0 
<35.0.1


Description
~~~~~~~~~~~
Dmitry Tantsur and Tuomo Tanskanen from the Metal3.io Security Team 
reported a vulnerability in Ironic's IPMI console backends. A project 
manager for the project marked as a ``node.owner`` can inject arbitrary 
commands which a conductor executes on console activation.
No console backends are enabled by default in Ironic. Only installations 
which have set ``[conductor]/enabled_console_interfaces`` to enable 
either ``ipmitool-shellinabox`` or ``ipmitool-socat`` are vulnerable.



Errata
~~~~~~
When the original advisory was published a CVE number was not assigned. 
CVE-2026-42510 was assigned on 2026-04-29.


Patches
~~~~~~~
- https://review.opendev.org/c/openstack/ironic/+/986418 
(2023.1/antelope (unmaintained))
- https://review.opendev.org/c/openstack/ironic/+/986417 (2024.1/caracal 
(unmaintained))
- https://review.opendev.org/c/openstack/ironic/+/986363 (2024.2/dalmatian)
- https://review.opendev.org/c/openstack/ironic/+/986362 (2025.1/epoxy)
- https://review.opendev.org/c/openstack/ironic/+/986361 (2025.2/flamingo)
- https://review.opendev.org/c/openstack/ironic/+/986235 (2026.1/gazpacho)


Credits
~~~~~~~
- Dmitry Tantsur from Metal3.io Security Team
- Tuomo Tanskanen from Metal3.io Security Team


References
~~~~~~~~~~
- https://launchpad.net/bugs/2148331
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42510


Notes
~~~~~
- A CVE request was filed with MITRE on 2026-04-27.
- Patches for unmaintained branches are provided as a courtesy.
- The ``ipmitool-shellinabox`` console interface is already scheduled
   for removal from Ironic for lack of security support for shellinabox.
   Security sensitive operators are strongly encouraged to stop use of
   this console interface immediately.


OSSA History
~~~~~~~~~~~~
- 2026-04-29 - Errata 1
- 2026-04-27 - Original Version


--
Goutham Pacha Ravi
OpenStack Vulnerability Management Team
https://security.openstack.org/vmt.html

Download attachment "OpenPGP_0x0638DAD3B82C3988.asc" of type "application/pgp-keys" (3241 bytes)

Download attachment "OpenPGP_signature.asc" of type "application/pgp-signature" (841 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.